MEDIUM🇵🇱 Wersja polska

CVE-2018-9840

CVSS 6.8v3.0pub. 2018-04-10upd. 2024-11-21

The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.

CVSS Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Signal

    APP
    Signal
    < 2.23.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-28345HIGH7.5same product

The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded...

CVE-2018-16132HIGH8.6same product

The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fai...

CVE-2020-5753MEDIUM5.3same product

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a ...

CVE-2025-5715LOW0.3same product

Odkryto podatność w Signal App 7.41.4 na Androidzie. Dotyczy ona nieznanego kodu komponentu Biometric Authenti...

CVE-2019-17192CRITICAL9.8PL ✓same vendor

Signal Android — przetwarzanie pakietów RTP przed odebraniem połączenia